<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Xinophobia &#187; Reports</title>
	<atom:link href="http://www.xinophobia.com/category/reports/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xinophobia.com</link>
	<description>You ARE paranoid and they ARE out to get you.</description>
	<lastBuildDate>Sat, 01 Aug 2009 23:25:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Pretty Great Firewall</title>
		<link>http://www.xinophobia.com/2008/07/pretty-great-firewall/</link>
		<comments>http://www.xinophobia.com/2008/07/pretty-great-firewall/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 05:49:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.xinophobia.com/?p=88</guid>
		<description><![CDATA[The strategy here is going to change a little bit. My original assumption about the Internet access control mechanisms was that the rules would be fairly static. This has proven to not be the case. Given the upcoming Olympic Games, I believe that access is going to be much less restrictive than usual and that [...]]]></description>
			<content:encoded><![CDATA[<p>The strategy here is going to change a little bit. My original assumption about the Internet access control mechanisms was that the rules would be fairly static. This has proven to not be the case. Given the upcoming Olympic Games, I believe that access is going to be much less restrictive than usual and that changes will be made very quickly.</p>
<p>As of 7/12/08:</p>
<p>Domains not reachable:</p>
<p>- facebook.com (was reachable on 6/29/08)<br />
- icanhascheezburger.com (was previously able to load site without pictures but now totally unreachable)<br />
- uncyclopedia.com<br />
- torproject.org<br />
- dit-inc.us</p>
<p>Domains reachable:</p>
<p>- cnn.com<br />
- bbc.co.uk<br />
- xkcd.com<br />
- wikipedia.org</p>
<p>The combination of Privoxy+Tor is again successful in accessing the blocked sites.<br />
I chose to use this method because of its usability: free, well-integrated into popular browsers, and easy to setup.</p>
<p>However, there are several importants caveats to using tor:</p>
<p>- The network as it exists will not support connections requiring a lot of bandwidth (i.e. bittorrent, massive file transfers, etc.). It will work but it will be extremely slow. I need to stress that such usage will also have a negative impact on other tor users.<br />
- The software is experimental and should not be relied upon for strong anonymity.<br />
- The most reliable source for software and updates (torproject.org) is not reachable without a working copy of Tor.<br />
- Very few entry nodes are reachable. This raises some serious questions about the immediate security and long-term viability of Tor.</p>
<p>In my 80 hours or so logged into a functional circuit, I have seen only three distinct entry nodes. From a security standpoint, it is easy to believe that these entry nodes are planted or otherwise compromised to allow monitoring. Even if the entries are legitimate, it wouldn&#8217;t be hard to shutdown the network entirely. I leave this as an exercise to the reader.</p>
<p>There is an interesting paper on timing attacks for any onion router network:<br />
Low-Resource Routing Attacks Against Anonymous Systems by Kevin Bauer, Damon McCoy, Dirk Grunwald, Tadayoshi Kohno, Douglas Sicker<br />
<a href="http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf" target="_blank"> http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf</a></p>
<p>There are many alternatives to Tor which I will decline to list here. One that I am investigating is FreeGate: <a href="http://dit-inc.us" target="_blank">dit-inc.us</a>.</p>
<p>I encourage readers to have a plan of action in case Internet access is restricted in their area. What tools do you have immediately available to facilitate a breakout? If you don&#8217;t usually encrypt communications (i.e. pgp or some variant), will you want/need to? How many of your contacts will you be able to reach via other means (secure or not)?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xinophobia.com/2008/07/pretty-great-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Great Firewall or Greatest Firewall?</title>
		<link>http://www.xinophobia.com/2008/06/great-firewall-or-greatest-firewall/</link>
		<comments>http://www.xinophobia.com/2008/06/great-firewall-or-greatest-firewall/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 02:57:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Reports]]></category>

		<guid isPermaLink="false">http://www.xinophobia.com/?p=18</guid>
		<description><![CDATA[(quick update, full post to follow&#8230;)
Sites that are accessible:
- Gmail over 128bit SSL
- International Google
- myspace.com (not confirmed entirely accessible)
- facebook.com (ssl login okay)
Domains not accessible:
- wordpress.com
- livejournal.com
- meetup.com
- bbc.co.uk
Tools used:
- Vidalia (Tor) and privoxy
- open proxies from proxy.org
Success on all blocked sites with the above combination.
It took a LONG time to grab the list [...]]]></description>
			<content:encoded><![CDATA[<p>(quick update, full post to follow&#8230;)</p>
<p>Sites that are accessible:</p>
<p>- Gmail over 128bit SSL</p>
<p>- International Google</p>
<p>- myspace.com (not confirmed entirely accessible)</p>
<p>- facebook.com (ssl login okay)</p>
<p>Domains not accessible:</p>
<p>- wordpress.com</p>
<p>- livejournal.com</p>
<p>- meetup.com</p>
<p>- bbc.co.uk</p>
<p>Tools used:</p>
<p>- Vidalia (Tor) and privoxy</p>
<p>- open proxies from proxy.org</p>
<p>Success on all blocked sites with the above combination.</p>
<p>It took a LONG time to grab the list of relays in the Tor network. Given how few entry points there were, I suspect that most of the entry points are blocked. Tor has to find at least one open entry, pull an updated list of relays and then try to build a connection. I would not rely upon this method in the long term. Sad, but true.</p>
<p>Note on open proxies: use as much caution as you would any unfamiliar website. Many open proxies are heavily polluted with ads, pop-ups and worse. Proxies based out of your country may be your best bet.</p>
<p>(The next update may take a while. I only slept 3 hours before my flight and am experiencing just a touch more jetlag than expected. Crashing in 3&#8230;2&#8230;1&#8230;)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xinophobia.com/2008/06/great-firewall-or-greatest-firewall/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
